Patents Assigned to CROWDSTRIKE, INC.
-
Patent number: 12731301Abstract: Data is received. Each datum therein has one of a plurality of categorical values associated with a categorical variable. Each datum is deterministically mapped to a respective one of a plurality of colors in a color space based on its categorical value. The color to which each datum is deterministically mapped is then transformed to yield a minimum threshold separation between the respective colors. A graphical representation comprising the color to which each datum is respectively deterministically mapped, and as transformed to yield the minimum threshold separation between the respective colors, is displayed.Type: GrantFiled: September 28, 2023Date of Patent: September 8, 2026Assignee: Crowdstrike, Inc.Inventor: Søren Skovsbøll
-
Publication number: 20260259978Abstract: A permissive computing resource service detects unauthorized hardware processing assigned to an auxiliary data processing unit (DPU). The DPU is commonly a graphics processing unit (GPU), but unauthorized hardware processing may be detected in other hardware accelerators. When tasks are assigned to the DPU/GPU, responsible parties are notified of the tasks assigned to the DPU/GPU. The responsible parties may thus respond with hardware processing authorizations that authorize the DPU/GPU to execute the tasks. If, however, one or more of the responsible parties fails to reply, or denies, then the DPU/GPU is not authorized to execute the tasks. The tasks, for example, may represent impermissible usage of the DPU/GPU or unsafe/abnormal behavior. The tasks may thus represent DPU hardware processing theft.Type: ApplicationFiled: March 1, 2025Publication date: September 3, 2026Applicant: CrowdStrike, Inc.Inventor: Andrew Southgate
-
Patent number: 12726496Abstract: Contextual session-based operational prediction greatly improves computer functioning. As a cloud service is provided, a current contextual session is generated using multiple events provided by the cloud service. The current contextual session is compared to a contextual session profile. The contextual session profile represents historical contextual sessions that have been historically logged in associated with the cloud service. If the current contextual session conforms to the contextual session profile, then the cloud service is normally operating as historically observed and may be predicted as normal operation. If, however, the current contextual session fails to conform to the contextual session profile, then the cloud service is not operating as historically observed and may be predicted as abnormal operation. Alerts and warning may be generated to notify of abnormal cloud service operation.Type: GrantFiled: January 11, 2024Date of Patent: September 1, 2026Assignee: CrowdStrike, Inc.Inventors: Michael Avraham Brautbar, Ryan Inghilterra, Xiaoning Li, Aditya Kapoor, Aashma Uprety
-
Patent number: 12724684Abstract: An artificial intelligence (AI) monitoring service detects, in real time or in near real time, misbehaving AI. The AI monitoring service monitors any of inputs to the AI, incoming/outgoing communications, API calls, inter-service/inter-container activities associated with the AI, and/or an output generated by the AI. Any activity conducted by, or associated with, the AI may be compared to an AI behavior profile defining permissible/impermissible activities. If any activity fails to conform to the AI behavior profile, alerts are sent and threat procedures are implemented. Very early stages of abnormal AI behavior are detected, thus quickly exposing abnormal AI behavior before the artificial intelligence can implement undesirable, or even harmful, actions.Type: GrantFiled: February 16, 2023Date of Patent: September 1, 2026Assignee: CrowdStrike, Inc.Inventor: Andrew Southgate
-
Patent number: 12712890Abstract: A cybersecurity event validation service provides a user-friendly scheme for detecting a cyberattack or threat. The cybersecurity event validation service accepts very simple, high-level, user-friendly descriptions of the cyberattack or threat. A user of the cybersecurity event validation service thus need not input detailed hardware/software events that specify the potential cyberattack or threat. The cybersecurity event validation service, instead, validates the user's very simple descriptions for correctness. If the user's very simple descriptions conform to basic rules or requirements, then the cybersecurity event validation service elegantly fills in the deep hardware and software details using context and inferences. The cybersecurity event validation service thus elaborates and enhances the user's very simple descriptions by supplying specific hardware/software details needed to detect the cyberattack or threat.Type: GrantFiled: November 1, 2023Date of Patent: August 18, 2026Assignee: CrowdStrike, Inc.Inventor: Providence Salumu
-
Patent number: 12705364Abstract: Prediction of matches between CPEs and banners greatly improves computer functioning. Many web services have an unknown common platform enumeration (CPE). When the CPE is unknown, a computer system is unable to obtain cybersecurity flaws and software fixes for a software product or web service. A similarity between the CPE and a service banner, though, accurately predicts a match the CPE and the web service. CPEs, for example, may thus be identified for old, obsolete, and uncomment software products and services.Type: GrantFiled: September 25, 2024Date of Patent: August 11, 2026Assignee: CrowdStrike, Inc.Inventors: Shaefer Drew, Moshe Shimon Perez, Michael Avraham Brautbar, Yotam Lichter
-
Patent number: 12705223Abstract: A value is assigned to a rate threshold for adding child nodes to a distinct parent node in a tree data structure. A first datum comprising a first variable assigned a first value and a second variable assigned a first value is added to the tree at a first timestamp, by adding to the first level in the tree a first parent node representing the first variable assigned the first value and adding to the second level in the tree a first child node representing the second variable assigned the first value and connected by a first directed edge from the first parent node. A second datum comprising the first variable assigned the first value and the second variable assigned a second value is received at a second timestamp. The method blocks adding to the second level in the tree a second child node representing the second variable assigned the second value and connected by a second directed edge from the first parent node when a rate based on the first timestamp and the second timestamp exceeds the rate threshold.Type: GrantFiled: September 2, 2022Date of Patent: August 11, 2026Assignee: Crowdstrike, Inc.Inventors: Daniel W. Brown, Johnathan Hoyt, Sseziwa A. Mukasa, Thomas R. Hobson
-
Patent number: 12699778Abstract: Techniques for using supervised machine learning to train risk models used to analyze group data for security risks are discussed herein. A system can receive a user input identifying risk values associated with categories or attributes of a group having access to computing resources. The system can use the risk model to generate a risk score for the group. The risk score can be used to further analyze aspects of the group or provide recommendations to reduce or eliminate security risks.Type: GrantFiled: November 21, 2023Date of Patent: August 4, 2026Assignee: CrowdStrike, Inc.Inventors: Christopher Balles, Kellen Arb, Michael Cosmadelis, Sean Corlin, Jeremy Fintel
-
Patent number: 12694108Abstract: Deception-based techniques for responding to security attacks are described herein. The techniques include transitioning a security attack to a monitored computing device posing as a computing device impacted by the security attack and enabling the adversary to obtain deceptive information from the monitored computing device. Also, the adversary may obtain a document configured to report identifying information of an entity opening the document, thereby identifying the adversary associated with the attack. Further, the techniques include determining that a domain specified in a domain name request is associated with malicious activity and responding to the request with a network address of a monitored computing device to cause the requesting process to communicate with the monitored computing device in place of an adversary server. Additionally, a service may monitor dormant domains names associated with malicious activity and, in response to a change, respond with an alert or a configuration update.Type: GrantFiled: October 3, 2023Date of Patent: July 28, 2026Assignee: CrowdStrike, Inc.Inventors: Adam S. Meyers, David F. Diehl, Dmitri Alperovitch, George Robert Kurtz, Sven Krasser
-
Patent number: 12694146Abstract: Multi-modal query processing greatly improves computer functioning. A single cybersecurity sensory nodal server concurrently processes standing queries, agent point queries, and agent fleet queries. The single cybersecurity sensory nodal server is dedicated to locally storing electronic data associated with a cybersecurity sensory agent installed at a client device. Because the single cybersecurity sensory nodal server locally stores the single source of the electronic data, the single cybersecurity sensory nodal server answers the standing queries, agent point queries, and agent fleet queries using less hardware resources, less network resources, less electrical energy, and less time.Type: GrantFiled: October 9, 2024Date of Patent: July 28, 2026Assignee: CrowdStrike, Inc.Inventors: Timothy Jason Berger, Marcus Andrew King, Thomas Francis Lyons, Brent Ryan Nash, James Robert Plush
-
Patent number: 12689642Abstract: A system and method of using generative AI to identify exposures of computing devices on computing networks to actual and/or potential threats. The method includes collecting a plurality of responses from a plurality of devices to a target device on a private network. The method includes providing the plurality of responses to a classification model trained to assign device descriptions for device responses based on semantic matching of the device responses to database data. The method includes assigning, by the processing device using the classification model, a plurality of device descriptions for the plurality of responses to the target device, each response is respectively associated with one or more device descriptions of the plurality of device descriptions. The method includes generating, based on the plurality of device descriptions, a status report comprising a list of network addresses associated with a group of devices having access to the target device.Type: GrantFiled: November 29, 2023Date of Patent: July 21, 2026Assignee: CrowdStrike, Inc.Inventors: Paul Sumedrea, Damian Monea
-
Patent number: 12688281Abstract: The present disclosure provides techniques for AI model-based detection explainability. A processing device obtains computer-readable text and an indication of a false positive detection of malicious behavior with respect to the computer-readable text by a cybersecurity system, The processing device obtains, via an artificial intelligence (AI) model trained to generate language, a reason for the false positive detection of the malicious behavior. The processing device provides an indication of the reason for the false positive detection to a destination device.Type: GrantFiled: May 30, 2024Date of Patent: July 21, 2026Assignee: CrowdStrike, Inc.Inventors: Diana Bolocan, Mihaela-Petruta Gaman
-
Publication number: 20260205476Abstract: IT asset discovery services and external attack surface management (or EASM) services identify computers, servers, smartphones, and other devices that are exposed to the public Internet. Any device that can connect to the public Internet may be vulnerable to cybersecurity attacks. The services identify a device exposed to the public Internet by generating an asset inventory discovery graph. Graphical nodes describe asset inventory investigative records, and edges between the graphical nodes describe asset inventory investigative methods. The nodes thus capture asset investigatory details (such as website URL, IP addresses, and HTML content), and the edges capture how the asset investigatory details were discovered (such as Internet searches, DNS records, and WHOIS records). The services use the asset inventory discovery graph to identify an entity's Internet-facing assets.Type: ApplicationFiled: January 13, 2025Publication date: July 16, 2026Applicant: CrowdStrike, Inc.Inventors: Michael Brian Goldgeier, Yaron Tal, Moshe Shimon Perez, Michael Glyer, Yotam Lichter
-
Patent number: 12682057Abstract: A cloud-based file integrity monitoring service identifies content changes to a computer file. An endpoint cybersecurity agent monitors its host client device for read/write and other operating system events associated with the computer file. When the endpoint cybersecurity agent detects each operating system event, the endpoint cybersecurity agent captures and reports, in real time or near real time, a snapshot of the file content representing the computer file. So, as the host client device changes the computer file with each operating system event, the endpoint cybersecurity agent uploads timestamped snapshots of the file content to a cloud-based file integrity monitoring service. The cloud-based file integrity monitoring service stores each snapshot of the file content, thus logging a change history for the computer file.Type: GrantFiled: May 30, 2024Date of Patent: July 14, 2026Assignee: CrowdStrike, Inc.Inventors: Silviu-Alexandru Badragan, Andrei-Viorel Cotiga, Adam Freund, Samantha Alyn Goresh, Ioan Tinca
-
Patent number: 12676833Abstract: A firewall receives a flow of data from a first computing resource destined to a second computing resource and searches, in a memory, a prefix tree data structure, the prefix data structure comprising a linked plurality of nodes corresponding to normalized criteria for each of a plurality of rules, for any rule in the plurality of rules that applies to controlling the received flow of data between the first computing resource and the second computing resource. If the search is successful, a set of rules in the prefix tree data structure is identified that apply to controlling the received flow of data from the first computing resource to the second computing resource in response to the searching. One of those rules in the set is then selected to control the received flow of data from the first computing resource to the second computing resource.Type: GrantFiled: January 28, 2022Date of Patent: July 7, 2026Assignee: Crowdstrike, Inc.Inventors: Keehun Nam, Tim Adams
-
Patent number: 12675570Abstract: Methods and systems implement computing systems configured to trigger a volatile memory scan based on execution of computer-executable instructions, and to downselect scope of a volatile memory scan. Such techniques for triggering scans are sufficiently selective to avoid volatile memory scans for each and every running process, or vast majority of running processes. Moreover, volatile memory scans are triggered responsively after the computer-executable instructions are run, so that target processes to be scanned have not yet terminated at the time of the volatile memory scan. Additionally, a variety of techniques are implemented to minimize the volatile memory scans adversely impacting computational performance of the computing system.Type: GrantFiled: August 11, 2023Date of Patent: July 7, 2026Assignee: CrowdStrike, Inc.Inventors: Jennifer Mankin, Blair Foster, Marc Leclair, Eric Kuhl
-
Publication number: 20260178829Abstract: An LLM log parsing service parses log data using at least one large language model. The LLM log parsing service, however, may evaluate multiple log parser candidates. Each log parser candidate parses a sample of the log data using the at least one large language model. The LLM log parsing service generates a log parser decision that selects which one of the log parser candidates best performs as a log parser. The LLM log parsing service then parses the log data using the best log parser.Type: ApplicationFiled: December 20, 2024Publication date: June 25, 2026Applicant: CrowdStrike, Inc.Inventors: James Robert Plush, Sean Berry
-
Patent number: 12665921Abstract: Techniques for calculating risk scores of entity assignments are discussed herein. The system generates a probability matrix using a collaborative filtering technique such as singular value decomposition. The probability matrix is populated with probability values for each entity representing a probability that, based on the various relationships or associations of that entity with other entities, the entity has been granted an assignment. Risk values are used to provide a weighting value to assignments, separating relatively higher risk assignments from relatively lower risk assignments. The system thereafter calculates a risk score for one or more of the entities using the information in the assignment matrix, the probability matrix, and the risk values. The system can flag or identity one or more entities whose risk scores do not meet various criteria.Type: GrantFiled: November 28, 2023Date of Patent: June 23, 2026Assignee: CrowdStrike, Inc.Inventors: Robert Molony, Michael Brautbar, Manu Nandan, Ciaran O'Brien
-
Publication number: 20260170133Abstract: A cybersecurity model assessment service assesses machine learning and/or artificial intelligence models for cybersecurity threats. The cybersecurity model assessment service may particularly assess a pickle file associated with an AI/ML model. A dynamic emulation reveals whether the pickle file represents normal or abnormal computer behavior. The dynamic emulation of the pickle file may thus reveal whether the AI/ML model is safe or unsafe to use.Type: ApplicationFiled: December 16, 2024Publication date: June 18, 2026Applicant: CrowdStrike, Inc.Inventors: Stefan Cicos, Alexandru-Constantin Ghita, Andrei Stoian, Paul-Danut Urian
-
Publication number: 20260172451Abstract: An endpoint cybersecurity reinforcement learning agent uses reinforcement learning to implement cybersecurity actions. The endpoint cybersecurity RL agent interfaces with a host operating system as an antimalware driver. The endpoint cybersecurity RL agent receives an event notification generated by the OS and determines a responsive cybersecurity action using the reinforcement learning. The endpoint cybersecurity RL agent implements the cybersecurity action via the OS. The endpoint cybersecurity RL agent thus greatly improves computer functioning by quickly learning to identify new/novel suspicious events and operations.Type: ApplicationFiled: December 16, 2024Publication date: June 18, 2026Applicant: CrowdStrike, Inc.Inventors: Arnd Korn, Ian Torres